Research into file-notification attacks on Linux
Sudheendra Raghav Neela, a member of a group of researchers from Graz University of Technology , has announced the release of research into file-notification attacks that would allow spying on user activity on Android, Linux, macOS, and Windows. The group has published a paper with details on the research as well as a web site with demonstrations of the vulnerabilities. On Linux, an attacker can…
Researchers from Graz University of Technology have unveiled findings on file-notification attacks that could enable spying on user activity across Android, Linux, macOS, and Windows systems. The group's research, detailed in a paper along with demonstrations on their website, highlights several vulnerabilities.
On Linux platforms, an attacker could exploit inotifywatch to monitor a directory, even without read access to the files, executing an inter-keystroke timing attack. This technique allows an attacker to observe the timing of keystrokes, potentially intercepting sensitive data. Moreover, the researchers discovered a method to launch UI-redress attacks, or clickjacking, specifically on KDE 5 and KDE 6.
By monitoring the /usr/bin/pkexec file, the attacker can detect when Polkit spawns an authentication prompt. This vulnerability could be exploited by overlaying a fake password window over the legitimate one, allowing the capture of user credentials.
Despite partial mitigations introduced in several Linux kernel versions released in January, these flaws remain exploitable. The research team has provided further details and a mitigation strategy on their website, emphasizing the importance of users being aware of these potential security threats.
Written by urgent.news from LWN's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.